当前位置: 首页 > 网络学院 > 服务端脚本教程 > PHP > PHP 安全技巧连载 #4[译]

PHP 制作 网站/服务器 监视脚本
PHP 单件模式
PHP 中使用正则表达式
PHP 防止 SQL 注入攻击
PHP 跨站点脚本攻击
PHP 防止用户操纵 GET 变量
PHP 防止远程表单提交

PHP 安全技巧连载 #4[译]

出处:互联网   整理: 软晨网(RuanChen.com)   发布: 2009-03-01   浏览: 844 ::
收藏到网摘: n/a

翻译:[email protected]

“Security through obscurity is no security at all.” so the adage goes. However, the flip side of that coin is, obscurity, when used as part of an overall strategy, is a good thing. There’s no sense in making things any easier for those with malicious intent. That brings us to our security tip for the day.


Give files and folders with critical information non-default names


Don’t rely on obscure names to keep your application safe. You should always check permissions, test for vulnerabilities with testing tools and keep an eye on your log files for suspicious activity. When designing your applications and web sites though, don’t make it easy for bad people to do bad things. Don’t use default or common names for your files and directories.


评论 (0) All

登陆 | 还没注册?